dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003

This is an old revision of the document!


FR-AG-003 — Artifact Import Packages

Crucible SHALL import identified Artifacts from a Transfer Bundle into a destination environment.

The system shall support artifact import packages.

Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-AG-003.

The source statement identifies a required import package but does not provide a fully testable formulation.

The following Specification Discipline and Authoring findings apply:

  • The system does not use the defined system name
  • shall does not follow the established uppercase normative convention
  • Support is a weak verb that does not identify the required behavior
  • Artifact import packages does not identify whether Crucible creates, verifies, stores, transfers, or imports the package contents
  • Artifact import packages does not use the defined Transfer Bundle concept
  • The source statement does not identify the Artifacts imported from the package
  • The source statement does not identify the destination environment
  • The source statement does not prescribe a package format, archive technology, storage medium, repository implementation, transfer mechanism, or integrity mechanism

The normalized Statement:

  • Replaces The system with Crucible
  • Replaces support with the direct behavior import
  • Uses the defined Transfer Bundle concept
  • Identifies the Artifacts as the imported subjects
  • Identifies a destination environment
  • Preserves one Transfer Bundle identity across export, transfer, receipt, and import
  • Preserves implementation independence
  • Retains one primary required behavior

The normalized Statement does not create a separate Artifact Import Package concept. The package consumed during import is the same Transfer Bundle created for export.

Separate requirements govern:

A Transfer Bundle is a controlled package prepared for transfer between environments.

The same Transfer Bundle may participate in the following sequence:

  • Crucible creates the Transfer Bundle in a source environment
  • An authorized process transfers the Transfer Bundle across a Transfer Boundary
  • A destination environment receives the Transfer Bundle
  • An applicable process verifies Transfer Bundle Integrity
  • Crucible imports identified Artifacts from the Transfer Bundle

The package does not become a different Artifact merely because it moves from an export context to an import context.

Preserving one Transfer Bundle identity maintains continuity among:

The import operation may process:

The import operation may use Transfer Bundle information to identify:

  • The Transfer Bundle identifier
  • The Transfer Bundle Revision
  • The included Artifacts
  • Artifact identifiers
  • Artifact Revisions
  • Artifact content digests
  • The source environment
  • The destination environment
  • The applicable Transfer Authorization
  • Transfer Bundle Integrity information
  • The creating actor or process
  • The creation time
  • The applicable Baseline

FR-AG-003 requires import of identified Artifacts from a Transfer Bundle. It does not independently authorize those Artifacts for operation, promotion, or deployment.

This requirement applies to:

  1. Verification SHALL identify the Transfer Bundle selected for import
  2. Verification SHALL identify the Artifacts selected for import from the Transfer Bundle
  3. Verification SHALL identify the destination environment
  4. Verification SHALL confirm that Crucible imports the identified Artifacts from the Transfer Bundle into the destination environment
  5. Verification SHALL confirm that the imported Artifacts correspond to the identified Artifacts contained in the Transfer Bundle

Verification may include:

  • Transfer Bundle import testing
  • Transfer Bundle content inspection
  • Manifest inspection
  • Artifact identifier comparison
  • Artifact Revision comparison
  • Content digest comparison
  • Destination repository inspection
  • Provenance inspection
  • Traceability inspection
  • Import log inspection

The verification record SHALL identify:

  1. The imported Transfer Bundle
  2. The Transfer Bundle identifier
  3. The Transfer Bundle Revision
  4. The imported Artifacts
  5. The Artifact identifiers
  6. The Artifact Revisions
  7. The package manifest
  8. The destination environment
  9. The destination repository
  10. The import result
  11. The generated Evidence

The wiki Backlinks function provides the current list of pages that reference FR-AG-003.

Incoming Traceability should be derived dynamically from backlinks rather than maintained as a duplicate manual list.

Backlinks identify incoming references but do not define the semantics of each relationship. Referencing pages should identify whether the relationship represents realization, refinement, verification, dependency, or another defined traceability relationship.

The Crucible Concept of Operations describes a connected-to-disconnected supply chain in which Artifacts and Dependencies are packaged within a Transfer Bundle, transferred from a Connected Environment, and imported into a Disconnected Environment.

FR-AG-003 establishes the required behavior for importing identified Artifacts from the Transfer Bundle into the destination environment.

The Transfer Bundle retains the same controlled identity through export, transfer, receipt, integrity verification, and import.

Phase 1

Not Assessed

Implementation status requires verification that Crucible imports identified Artifacts from a Transfer Bundle into a destination environment.

Draft

The source System Requirements Specification identifies Version 1.1 as a draft.


This requirement page should retain the stable requirement identifier FR-AG-003.

Changes to the Statement SHALL preserve the approved intent of the source requirement.

The Source Statement should preserve the original visible wording from the controlling System Requirements Specification while linking applicable words and phrases to the controlling Terms and Definitions entries.

The source phrase artifact import packages maps to the defined Transfer Bundle concept.

The Statement should remain limited to importing identified Artifacts from a Transfer Bundle into a destination environment.

The requirement should not introduce separate Artifact Export Package and Artifact Import Package artifact types unless the controlling architecture later defines different package structures or identities.

Requirements for Transfer Authorization, transfer across a Transfer Boundary, verification of Transfer Bundle Integrity, Artifact approval, Image Promotion, and deployment should remain in their applicable requirement pages.

Verification criteria should test only the behavior stated in the normalized Statement and should not introduce additional normative obligations.

Incoming Traceability should use the wiki Backlinks function rather than a manually maintained list.

To reference this requirement Statement from another wiki page, insert:

{{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003#Statement&noheader&nofooter&noeditbtn}}

Do not rename this page after an external citation unless a redirect or move plan is in place.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/02-crusible/99-annexes/annex-c-requirements/03-functional-requirements/03-05-air-gap-operations/fr-ag-003.1784561804.txt.gz
  • Last modified: 2026/07/20 08:36
  • by nick_dido